CVE-2013-2233 — Redhat Ansible vulnerability
Severity
7.4HIGHNVD
EPSS
0.4%
top 42.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 4
Latest updateOct 10
Description
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2
Affected Packages3 packages
🔴Vulnerability Details
4📋Vendor Advisories
1Debian▶
CVE-2013-2233: ansible - Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-...↗2013
💬Community
3Bugzilla▶
CVE-2013-2233 ansible: Does not cache SSH host keys (preventing possibility of server's host key to be checked against system host keys)↗2013-07-03
Bugzilla▶
ansible: CVE-2013-2233 ansible: Does not cache SSH host keys (preventing possibility of server's host key to be checked against system host keys) [fedora-all]↗2013-07-03
Bugzilla▶
ansible: CVE-2013-2233 ansible: Does not cache SSH host keys (preventing possibility of server's host key to be checked against system host keys) [epel-6]↗2013-07-03